As of 13 August 2026, AI can only partly check your email marketing consent process under UK PECR.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
2 hoursto something you’d act on.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita professional
What the alternative costsA solicitor or data protection specialist is the alternative for a legally accountable review; no price is stated here.
If this goes wrong, you continue sending marketing without valid consent or rely on an exception that does not apply, leaving your business exposed to complaints and enforcement.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, chat-fluent skill, and roughly 2 hours until you can act on the result.
How to actually do it
- Open the current ICO guidance on electronic mail marketing and the relevant PECR provisions, then save the source links you will use for checking.
- Gather the full sign-up wording, screenshots or a written description of each consent journey, the list source, consent logs, privacy information, suppression-list process and unsubscribe workflow.
- Separate the evidence by recipient type, including individuals, sole traders, limited companies, existing customers and contacts obtained from another organisation.
- Paste the evidence and the self-contained prompt into a chatbot, replacing each bracketed slot and asking it to identify missing facts rather than fill them in.
- Copy each finding into a review table with columns for evidence, PECR or UK GDPR issue, ICO or legislation source, internal check and professional confirmation needed.
- Compare every cited proposition with the saved ICO or legislation source, checking that the source is current on 2026-08-13 and that the facts in your records support the model's conclusion.
- Send the table, underlying evidence and unresolved issues to a solicitor or data protection specialist before changing the process or relying on an exception.
Prompt
Check the email marketing consent process below against UK PECR and the related UK GDPR requirements. This is a compliance gap analysis, not professional advice. Use only current, attributable sources, prioritising the ICO and legislation.gov.uk, and provide a link and access date for every legal proposition. If you cannot verify a point from a current source, label it "needs professional confirmation" rather than guessing. Separate the findings into: 1. direct marketing rules that appear to apply; 2. whether the consent wording is specific, informed, freely given and capable of being withdrawn; 3. whether the collection method creates evidence of consent; 4. whether any soft opt-in or other exception is being relied on, and what facts must be true for it to apply; 5. unsubscribe and suppression-list handling; 6. use of bought, shared or transferred lists; 7. gaps, contradictions and missing evidence; 8. practical actions, ranked by legal risk and urgency. For each finding, quote the relevant process text or identify the missing evidence, explain the issue in plain English, cite the source, and state whether the point can be checked internally or needs a solicitor or data protection specialist. Do not declare the process compliant, invent facts, infer consent from silence or pre-ticked boxes, or give a definitive legal conclusion. Business context: [business type and location] Recipients: [individuals, sole traders, companies, or mixed] Messages: [what the emails promote] List source: [how each address was collected or obtained] Consent wording and sign-up journey: [paste in full] Records retained: [what is recorded, where, and for how long] Unsubscribe process: [describe it] Soft opt-in or other exception relied on: [describe it] Process and documents to review: [paste the full process, wording, screenshots as text, supplier terms and relevant records]
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot establish what happened when a contact was collected if your consent records do not prove it.
- AI cannot decide from incomplete facts whether the soft opt-in or another PECR exception applies to your particular campaign.
- AI cannot provide legal accountability for continuing to send messages or for choosing not to change the process.
- AI cannot replace a solicitor or data protection specialist where the consequences of a wrong interpretation are serious.
- AI cannot independently test every supplier, list broker or marketing platform setting unless you provide reliable evidence from each one.
What caps this at PARTLY: legal accountability, regulated advice and verification cost.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 0 |
| Effort delta | 1 |
| Total | 5 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT check whether my email consent process follows UK PECR?
- It can produce a useful gap analysis from your wording, collection journey and consent records. It cannot give your business legal accountability, and a solicitor or data protection specialist should confirm unresolved or high-risk points.
- Can AI tell me if I have valid consent to send marketing emails?
- It can identify whether your records appear to show a clear consent request, an affirmative action, suitable information and a withdrawal route. It cannot repair missing evidence or make a definitive legal decision where the facts or an exception are unclear.
- Can I use the soft opt-in for email marketing under PECR?
- AI can list the facts that normally need checking, such as how the address was collected, what was offered and whether the marketing is sufficiently related. The application to your campaign needs checking against current ICO guidance and, in a serious case, by a solicitor or data protection specialist.
- Is an AI review enough for UK email marketing compliance?
- No. Use it to organise evidence, surface gaps and prepare questions, then verify the sources and have a professional assess material uncertainty. This is not professional advice.
Nearby answers
- Can AI act as my business's data protection officer?NO
- Can AI audit my website cookies for PECR compliance?PARTLY
- Can AI build a data protection policy for my UK business?PARTLY
- Can AI check whether an AI tool creates UK GDPR risks for my business?NO
- Can AI check whether my international data transfers comply with UK GDPR?NO
- Can AI check my privacy notice for UK GDPR compliance?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.